Data leak [loss] $55M+

"Hacker steals $55 million from bZx DeFi platform"

2021-11-05 [vendor] bZx
Primary Source ↗
Financial Loss $55.0M (55,000,000 USD)

Incident Details

An attacker fooled a developer of the bZx decentralized finance platform into opening a Word document with a malicious macro, which ran a script that gave the attackers access to the developer’s crypto wallet private keys. They were able to gain access not only the developer’s personal wallet keys, but to two keys to bZx wallets. The attacker made off with approximately $55 million. bZx subsequently tried to offer the attacker a bounty to return the funds, though they were not successful.

Total loss estimated at $55,000,000.

Technical Details

Initial Attack Vector
Smart contract exploit / hack
Vendor / Product
bZx

Timeline

  1. 2021-11-05 Breach occurred
  2. 2021-11-05 Publicly disclosed